PROPER WEBOPS
Privacy Policy & Security Standards
Effective Date: August 27, 2026 | Last Updated: August 2026
Proper WebOps (“we”, “us”, or “our”), operated at properwebops.com, provides enterprise-grade WordPress performance, security, maintenance, and technical operations services for real estate and architecture organizations. We are fully committed to protecting the privacy, confidentiality, and integrity of the personal and technical data entrusted to us by our clients and website visitors.
Security & Privacy Commitment: Proper WebOps adheres strictly to the General Data Protection Regulation (GDPR – EU 2016/679), the ePrivacy Directive, and international security best practices. We enforce strict data minimization, end-to-end encrypted administrative workflows, and zero-knowledge data credential storage.
1. Data We Collect and Process
Depending on whether you visit our website, request a site scan, or subscribe to our WebOps services, we collect the following categories of data:
Account & Contact Information: Name, business email address, company name, phone number, and billing details provided during consultation, audit requests, or subscription onboarding.
Client Platform Technical Data: Website URL, server architecture metadata, IP addresses, database structures, plugin/theme inventories, SSL certificate statuses, and system log files necessary to perform security audits, backups, and speed optimizations.
Access Credentials: Temporary administrator logins, API keys, or connector authentication tokens provided via our encrypted submission vaults or connector plugin.
Automated Telemetry & Analytics: IP address, browser type, device information, operating system, and referral URLs collected via privacy-friendly server logs for security and performance diagnostics.
2. How We Use Your Data
We process data strictly for necessary operational, security, and contractual purposes:
To provision, maintain, and optimize your web platform infrastructure.
To execute 24/7 uptime monitoring, security patching, endpoint form checks, and malware scanning.
To generate monthly transparent performance, health, and security reports.
To communicate service updates, emergency technical patches, or billing notices.
To detect, prevent, and remediate cyber threats, unauthorized access, or server vulnerabilities.
3. Security Standards & Access Protocol
We apply robust technical and organizational security measures (TOMs) aligned with ISO/IEC 27001 standards to prevent unauthorized disclosure, alteration, or destruction of client assets:
Zero-Password Onboarding: Access to client environments is established primarily via our custom, lightweight connector plugin or end-to-end encrypted secret vaults (e.g., 1Password / Vaultwarden). We do not store administrative passwords in plaintext or transmit them via unencrypted communication channels.
Staging-First Operations: All core updates, database cleanups, and custom patch deployments are verified in isolated staging environments before production release.
Isolated Off-Site Snapshot Encryption: System backups and off-site snapshots are encrypted in transit (TLS 1.3) and at rest (AES-256) on isolated cloud storage endpoints.
Least Privilege Access: Internal staff access is strictly restricted based on role and duty requirements. Access logs are audited regularly.
4. Data Sharing & Third-Party Processors
We never sell, rent, or trade personal or technical data to third parties. We share data only with trusted, GDPR-compliant infrastructure subprocessors essential for service delivery:
Cloud & Backup Storage: Enterprise infrastructure providers (e.g., AWS S3, Cloudflare, Hostinger CDN) for encrypted off-site backups and edge routing.
Monitoring & Reporting Tools: Automated uptime, endpoint pinging, and management infrastructure (e.g., WP Umbrella framework).
Transactional Email & CRM: Secure email delivery services (e.g., Brevo) for transactional notifications and monthly report dispatch.
Legal Compliance: If required by law, subpoena, or court order to protect our rights, client assets, or public safety.
5. Data Retention & Deletion
Client Credential Tokens: Temporary administrative access tokens and connector credentials are immediately revoked or purged upon termination of service or task completion.
System Backups: Off-site backup snapshots are retained according to the active service plan agreement (typically 30 to 90 days) and are permanently purged upon contract cancellation.
Business & Billing Records: Retained for the statutory period required under applicable corporate and tax legislation.
6. Your Rights under GDPR
If you are residing in the European Economic Area (EEA) or UK, you hold the following rights regarding your personal data:
Right to Access & Portability: Request a copy of the personal data we hold about you.
Right to Rectification: Request correction of inaccurate or incomplete records.
Right to Erasure (“Right to be Forgotten”): Request the deletion of your personal data when no longer legally required.
Right to Restrict or Object: Restrict processing or object to direct marketing and processing based on legitimate interest.
To exercise any of these rights, contact our Data Protection Lead at privacy@properwebops.com.
7. Cookies & Tracking Technologies
Our site uses essential functional cookies necessary for security, session state, and load balancing. We do not use invasive third-party cross-site tracking scripts. Any performance analytics collected are anonymized and aggregated.
8. Updates to This Policy
We may update this Privacy Policy to reflect technical, legal, or operational modifications. Material changes will be communicated via our website or direct email notification to active clients.
9. Contact Information
For questions regarding this Privacy Policy, security practices, or data handling, please contact:
Proper WebOps Data Protection Team
Website: properwebops.com
Email: privacy@properwebops.com / support@properwebops.com
